CVE-2026-4371

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9. (en) A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

27 Mar 2026, 18:05

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=2023493 - () https://bugzilla.mozilla.org/show_bug.cgi?id=2023493 - Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2026-23/ - () https://www.mozilla.org/security/advisories/mfsa2026-23/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2026-24/ - () https://www.mozilla.org/security/advisories/mfsa2026-24/ - Vendor Advisory
First Time Mozilla
Mozilla thunderbird
CPE cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

25 Mar 2026, 17:17

Type Values Removed Values Added
CWE CWE-126
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

25 Mar 2026, 15:41

Type Values Removed Values Added
Summary
  • (es) Un servidor de correo malicioso podría enviar cadenas malformadas con longitudes negativas, haciendo que el analizador lea memoria fuera del búfer. Si un servidor de correo o una conexión a un servidor de correo fueran comprometidos, un atacante podría hacer que el analizador funcione mal, potencialmente bloqueando Thunderbird o filtrando datos sensibles. Esta vulnerabilidad afecta a Thunderbird &lt; 149 y Thunderbird &lt; 140.9.

24 Mar 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 21:16

Updated : 2026-04-13 15:17


NVD link : CVE-2026-4371

Mitre link : CVE-2026-4371

CVE.ORG link : CVE-2026-4371


JSON object : View

Products Affected

mozilla

  • thunderbird
CWE
CWE-126

Buffer Over-read